BlueMoon: The Exploit Kit Powering Multiple Spy Groups and Zero-Day Attacks
Summary
BlueMoon is a modular exploit kit that chains two Chrome V8 vulnerabilities with a Windows kernel privilege-escalation flaw. A victim only needs to open an attacker-controlled link in a vulnerable Chromium-based browser for the chain to attempt browser code execution, escape V8 isolation, elevate privileges, inject into Chrome's broker process, and launch an operator-selected payload. BlueMoon is not a single malware payload; it is an exploitation framework that gives different operators a reusable path from a malicious webpage to code execution on a Windows endpoint. The kit was observed in campaigns attributed to or associated with four espionage-focused clusters: TA412, also tracked as APT31; UNK_LateNight; UNK_DoubleCheck; and UNK_QuietRacket. The downstream malware varied by operator, showing that BlueMoon functions as an access and payload-delivery layer rather than a fixed backdoor.
The impact depends on the operator. Observed campaigns delivered the GemStone browser-surveillance and credential-theft extension, ShadowPad, Rust-based loaders, DLL-sideloading chains, and custom malware. Successful compromise can expose browser cookies, active sessions, browsing activity, screenshots, credentials, and other information reachable from the infected endpoint. Because the exploit kit was adopted rapidly by several clusters, the same browser-and-Windows chain can lead to different post-exploitation behavior.
Background
Proofpoint first observed BlueMoon in TA412 activity on August 28, 2026. Within days, three other espionage-focused clusters were using variants of the same kit. Most of the observed activity had a suspected China nexus, but Proofpoint cautioned that some use remained unattributed and that access to BlueMoon might not be exclusive to China-aligned actors.
The two V8 vulnerabilities were patch-gap zero-days during the observed attacks: fixes were visible in public upstream Chromium source before corrected stable browser builds reached users. That gap gave exploit developers an opportunity to study the code changes and weaponize them. BlueMoon variants differed in packaging, obfuscation, landing pages, redirects, telemetry, and payloads, yet retained the same exploitation sequence and embedded components, strongly indicating a common underlying source.
TA412 used tailored lures involving internship requests and the AAS-in-Asia 2026 conference. Other clusters targeted US aerospace organizations, a Vietnamese manufacturing company, and entities in Singapore and Indonesia. Victims who opened a malicious link were shown a temporary loading page while exploitation was attempted and were then redirected to a legitimate website, reducing the chance that the failed or completed exploit would immediately raise suspicion.
Vulnerability Details
| CVE | Weakness | EPSS Score | CVSS Score |
|---|---|---|---|
| CVE-2026-85046 | Type confusion in Chrome V8's optimizing JIT path | 1.46% | 8.8 High (CVSS v3.1) |
| CVE-2026-87491 | Out-of-bounds write in V8 | 1.00% | 8.8 High (CVSS v3.1) |
| CVE-2026-85880 | CWE-122 heap-based buffer overflow in Windows ALPC | 0.57% | 7.8 High (CVSS v3.1) |
Attack Methodology
- Targeted delivery: An operator sends a tailored phishing email containing a link to an attacker-controlled landing page.
- Exploit orchestration: The landing page loads BlueMoon's JavaScript launcher, which checks the browser environment, manages retries, and prepares three embedded components.
p1denotes the first payload, a reconnaissance DLL;p2denotes the second payload, a Windows local privilege-escalation DLL; andppdenotes the position-independent process-injection shellcode launcher. - Renderer exploitation: CVE-2026-85046 abuses V8 type confusion to produce address-disclosure and forged-object primitives, leading to arbitrary read and write access within the V8 heap.
- V8 sandbox escape: CVE-2026-87491 corrupts WebAssembly metadata and replaces compiled function bodies with shellcode from
p1. - Host reconnaissance: The reflectively loaded
p1DLL collects the Windows build, token integrity level, andkernelbase.dllversion to decide whether the host is suitable for the kernel exploit. - Privilege escalation: On a supported Windows build,
p2exploits CVE-2026-85880 to gain kernel read and write capabilities and enableSeDebugPrivilege. - Broker-process injection: The
pplauncher injects aCreateProcessstub and command line into Chrome's parent broker process, moving execution outside the renderer sandbox. - Payload delivery: The default command uses
curlto save an executable under%TEMP%and run it. The delivered payload depends on the operator and campaign.
Indicators of Compromise (IOCs)
The following defanged indicators were published by Proofpoint and cover the shared exploit kit plus representative infrastructure and payloads from all four observed clusters. Defenders should correlate them with phishing telemetry, browser activity, endpoint events, and the time of observation rather than treating a single historical indicator as conclusive evidence.
| Cluster | Indicator | Type | Description |
|---|---|---|---|
| TA412 | 779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096d | SHA-256 | driver-html.js, BlueMoon exploit JavaScript |
| TA412 | 7d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288 | SHA-256 | ChromeUpdate.exe or msgbox.exe |
| TA412 | secboxes[.]com | Domain | Exploit delivery and payload download domain |
| TA412 | msbenefit[.]com | Domain | Exploit delivery and payload download domain |
| TA412 | extension-management-portal.centerfjdr658.workers[.]dev | Hostname | GemStone extension command-and-control |
| UNK_LateNight | a4a6a04d85eca8d584d939d2437c85a4f291207d8042f2ec002838e336b72ef5 | SHA-256 | Index.js, BlueMoon exploit JavaScript |
| UNK_LateNight | 295fc584f75e94108c9be945977db33ed80421f5d374eab188587c911dffd915 | SHA-256 | msgbox.exe |
| UNK_LateNight | airproducts[.]ink | Domain | BlueMoon exploit delivery domain |
| UNK_LateNight | ms.checrity[.]com | Hostname | ShadowPad command-and-control |
| UNK_LateNight | 79.133.56[.]90 | IP address | Fallback ShadowPad command-and-control server |
| UNK_QuietRacket | b34802a646fc4a8f07ffa09a5fda8bf7327446b22e3d7bb5163dafa1e2a8bb2b | SHA-256 | Loader.js, BlueMoon exploit JavaScript |
| UNK_QuietRacket | yhv41nji.workers[.]dev | Hostname | BlueMoon exploit delivery |
| UNK_QuietRacket | eduac.workers[.]dev | Hostname | Exploit delivery, payload download, and command-and-control |
| UNK_QuietRacket | getaiexo[.]com | Domain | Command-and-control domain |
| UNK_DoubleCheck | ac6bbc4b1f1c62e308781329183a46e18f454c27e66bffa09f343b53ac622b69 | SHA-256 | font-01.js, BlueMoon exploit JavaScript |
| UNK_DoubleCheck | vncdc.mailtbox.workers[.]dev | Hostname | BlueMoon exploit delivery |
| UNK_DoubleCheck | homepage.brianwilli[.]com | Hostname | Payload download host |
| UNK_DoubleCheck | fracons[.]com | Domain | Command-and-control domain |
MITRE ATT&CK Mapping
The following mapping is an analytical alignment of publicly reported BlueMoon behavior with the closest MITRE ATT&CK Enterprise techniques. BlueMoon does not currently have a dedicated MITRE software entry, and payload-specific techniques may not apply to every operator.
| Technique ID | Technique Name | Tactic | Observed BlueMoon Behavior |
|---|---|---|---|
| T1566.002 | Spearphishing Link | Initial Access | Operators sent tailored emails containing links to attacker-controlled exploit pages. |
| T1203 | Exploitation for Client Execution | Execution | The landing page exploited two V8 vulnerabilities to execute attacker-controlled code through the victim's browser. |
| T1082 | System Information Discovery | Discovery | The p1 DLL collected the Windows version, build, token integrity level, and kernelbase.dll version. |
| T1068 | Exploitation for Privilege Escalation | Privilege Escalation | CVE-2026-85880 was used to gain kernel read and write capabilities and elevate the renderer token. |
| T1055 | Process Injection | Defense Evasion / Privilege Escalation | The pp launcher injected executable code and a command line into Chrome's parent broker process. |
| T1105 | Ingress Tool Transfer | Command and Control | The default post-exploitation command used curl to retrieve and execute an operator-selected payload. |
| T1176 | Software Extensions | Persistence | TA412 installed the GemStone Chromium extension and modified protected browser preferences so it would load persistently. |
| T1071.001 | Web Protocols | Command and Control | GemStone used HTTP-based registration, heartbeat, ingestion, screenshot upload, and command-polling endpoints. |
| T1113 | Screen Capture | Collection | The GemStone extension supported screenshot collection and upload. |
| T1539 | Steal Web Session Cookie | Credential Access | GemStone requested browser cookie access and functioned as a browser-surveillance and credential-theft backdoor. |
Visual Attack Flow
The victim receives a tailored email and opens a link to an actor-controlled landing page.
The page checks the environment, orchestrates retries, and loads the browser exploit chain.
V8 type confusion creates arbitrary read and write access inside the V8 heap cage.
Corrupted WebAssembly metadata transfers execution to the embedded p1 shellcode and reconnaissance DLL.
BlueMoon checks the Windows build and token state to determine whether to run the kernel exploit.
The p2 DLL obtains kernel read and write access and enables SeDebugPrivilege.
The pp launcher injects a CreateProcess stub into the parent broker process.
The chain downloads and runs GemStone, ShadowPad, a Rust loader, a DLL-sideloading package, or another campaign-specific payload.
Mitigation
- Update Chrome and Chromium-based browsers: Deploy Chrome 153.0.8010.36/.37 or later so both V8 vulnerabilities are remediated. Verify that Edge, Brave, Vivaldi, and other Chromium-based browsers have incorporated equivalent fixes.
- Apply Microsoft security updates: Install the applicable September 2026 Windows update for CVE-2026-85880. Migrate unsupported Windows systems to supported releases rather than relying only on endpoint controls.
- Block and hunt for published indicators: Search DNS, proxy, email, EDR, and firewall telemetry for the defanged infrastructure and hashes above. Use Proofpoint's complete indicator set for broader coverage.
- Detect the post-exploitation chain: Alert on Chrome renderer processes opening higher-privileged browser processes, remote-thread creation in Chrome's broker, and browser-initiated commands resembling
curl -sS -o %TEMP%. - Inspect Chromium profiles: Investigate unexpected browser termination followed by relaunch with
--restore-last-session, unauthorized extension installation, modification of protected preference files, or the directoryC:\Users\Public\stomp_ext. - Contain confirmed infections: Isolate affected endpoints, preserve browser and EDR evidence, remove malicious extensions, rotate exposed credentials, revoke active web sessions, and rebuild the endpoint when kernel-level exploitation or process injection is confirmed.
- Reduce phishing exposure: Block newly registered and lookalike domains, detonate links in an isolated browser, and train high-risk users to report unexpected internship, conference, business-development, and supplier outreach.
Instantly Fix Risks with Saner Patch Management
Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.
It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.
Experience the fastest and most accurate patching software here.




